Compliance
Device Control Compliance: USB and Removable Media Requirements
Device control compliance is the enforcement and documentation of policies that govern how removable storage and peripheral devices connect to, interact with, and transfer data across endpoints.
Device control compliance is the enforcement and documentation of organizational policies governing how removable storage and peripheral devices connect to, interact with, and transfer data across endpoints. USB drives, external hard disks, optical media, and other removable peripherals represent persistent data-exfiltration and malware-introduction risks. Device-control software helps organizations authorize, restrict, monitor, and document peripheral access in ways that align with applicable regulatory and framework requirements.
Device-control software supports compliance. It does not guarantee it. Compliance depends on written policies, governance processes, risk assessments, documented exceptions, and evidence retained over time.
Most cybersecurity frameworks do not require organizations to disable every USB port. They require organizations to authorize, restrict, protect, monitor, and document the use of removable media according to data sensitivity and risk.
What is device control compliance?
It sits within a broader set of endpoint and data-protection controls:
| Control area | Purpose |
|---|---|
| Device control | Controls which peripheral devices can connect |
| Removable-media management | Governs media ownership, use, storage, and disposal |
| Encryption | Protects data stored on permitted media |
| Endpoint DLP | Controls which data can be transferred |
| Malware protection | Scans removable media for malicious content |
These areas overlap but are not interchangeable. A device-control policy that blocks unauthorized USB devices addresses a different objective than an encryption policy that protects data on permitted ones. Effective compliance programs address each layer.
Which cybersecurity frameworks require USB and removable-media controls?
Several major frameworks include explicit or risk-based requirements for removable-media governance. None universally mandates disabling all USB ports. Applicable obligations depend on the organization's scope, the data it handles, and its risk assessment.
| Framework | Who it applies to | Relevant requirement | What the framework expects | Supporting device-control measures |
|---|---|---|---|---|
| NIST SP 800-171 Rev. 3 | Organizations handling CUI | Media protection and system-use controls | Control removable-media use and prohibit media without an identifiable owner | Device allowlisting, serial-number identification, access restrictions, logging |
| ISO/IEC 27001:2022 | Organizations operating an ISMS | Annex A.7.10, Storage media | Manage media acquisition, use, transport, storage, and disposal | Access policies, encryption enforcement, activity records |
| PCI DSS v4.0.1 | Organizations handling payment-card data | Requirements 9.4 and 5.3.3 | Protect account-data media and scan removable media when inserted or connected | Media access restrictions, inventory, malware scanning, audit logs |
| NIS2 | Covered essential and important entities | Article 21 and Implementing Regulation 2024/2690 | Apply risk-management measures; covered entities under 2024/2690 face specific removable-media obligations | Authorization, technical prohibition of unauthorized connections, scanning, logging |
| DORA | EU financial entities | ICT risk-management requirements | Protect ICT assets through proportionate access and security controls | Risk-based peripheral restrictions, logging, exception management |
| Australian ISM | Australian government systems and relevant organizations | Current removable-media controls | Authorize, register, label, restrict, sanitize, and track removable media | Hardware allowlisting, device records, serial-number controls |
The table maps frameworks to supporting implementations. Explicit regulatory mandates differ from risk-based obligations: both types appear in the sections below.
NIST SP 800-171 removable-media requirements
Who must comply with NIST SP 800-171?
NIST SP 800-171 applies to non-federal organizations that process, store, or transmit Controlled Unclassified Information (CUI) on behalf of federal agencies. This includes defense contractors, research institutions, and commercial suppliers operating under federal contracts that reference DFARS or equivalent CUI-protection requirements. Compliance is typically a contractual condition, with CMMC assessments increasingly used to verify it.
What does NIST require for removable media?
NIST SP 800-171 Rev. 3 includes media protection controls requiring organizations to:
- Restrict or prohibit defined types of system media on system components
- Prohibit removable system media without an identifiable owner
- Protect and control portable storage devices containing CUI during transport
- Sanitize or destroy removable media before disposal or reuse
- Mark media with necessary CUI markings and distribution limitations
Device-control measures that support NIST compliance
- Device allowlisting
Only pre-approved devices, identified by serial number or hardware identifier, are permitted to connect. Media without an identifiable owner is blocked at the endpoint.
- Access restrictions
Users and endpoints that do not require removable-media access have it disabled by policy. Access is granted based on role and business need.
- Connection and activity logging
Organizations should determine whether removable-media connections and file activity are selected auditable events based on their audit, investigation, and CUI-protection requirements. Where they are, logs capture user identity, device identifier, timestamp, and endpoint.
- Media sanitization controls
Policies define how devices must be handled before reuse or disposal. Activity logs provide supporting evidence.
- Audit evidence
Assessors reviewing NIST compliance typically examine documented policies, configuration records showing device restrictions, access logs covering the assessment period, exception records, and evidence of periodic policy review.
ISO 27001 USB and removable-media controls
ISO 27001 Annex A.7.10 requirements
ISO/IEC 27001:2022 addresses storage media governance under Annex A.7.10. The control requires organizations to manage storage media across its entire lifecycle — acquisition through use, transport, storage, and disposal — in accordance with the organization's classification and handling requirements. Organizations must establish procedures for the secure handling of media containing sensitive information and ensure disposal renders data unrecoverable.
Does ISO 27001 require USB ports to be blocked?
No. ISO 27001 does not require organizations to disable USB ports universally. The standard requires organizations to select controls appropriate to their risk assessment and document those selections in a Statement of Applicability. Depending on the assessed risk, organizations may block USB access, restrict it to approved devices, or monitor permitted use — provided the rationale is documented and reviewed.
Device-control measures that support ISO 27001
- Media lifecycle management
Policies cover acquisition, authorized use, transport, storage, and secure disposal, with records demonstrating each stage is controlled.
- Authorization and accountability
Approved media is assigned to specific users or roles. Unapproved media is blocked or flagged.
- Encryption coordination
Where media carries sensitive data, organizations can combine device-control restrictions with approved removable-media encryption tools or policies to enforce protection before transfer.
- Secure disposal
Policies define sanitization requirements. Logs and disposal records support evidence of compliance.
- Policy enforcement and review
Device-control configurations are reviewed at defined intervals and after significant organizational changes. Review records are retained.
PCI DSS removable-media requirements
Which PCI DSS requirements apply to removable media?
PCI DSS v4.0.1 addresses removable media primarily under two requirements:
Requirement 9.4 covers the physical and logical protection of media containing account data. This includes restricting access, maintaining inventories of media, securing media during transport, and ensuring secure destruction when media is no longer needed.
Requirement 5.3.3 requires that anti-malware mechanisms perform automatic scanning or continuous behavioral analysis when removable electronic media is inserted, connected, or mounted to a system — unless the organization documents a risk analysis concluding that the media presents no risk of malware to the cardholder data environment.
Does PCI DSS require USB blocking?
No. PCI DSS does not require organizations to disable USB ports universally. It requires organizations to protect account-data media, maintain controlled access, and scan removable media for malware when connected to in-scope systems where applicable. Organizations that permit removable-media use within their cardholder data environment must implement appropriate controls and document them.
Device-control measures that support PCI DSS
- Media access restrictions
Access to removable media is limited to individuals with a documented business need. Controls prevent unauthorized connection to in-scope systems.
- Media classification and inventory
All media containing account data is classified, labeled, and tracked. Inventory records are maintained and periodically verified.
- Restricted access
User- and device-level controls determine who can connect removable media to cardholder data environment endpoints.
- Secure destruction
Policies and records demonstrate that media containing account data is destroyed using methods that render data unrecoverable before disposal. This is typically a process and physical-security control rather than a device-control software function.
- Malware scanning
Requirement 5.3.3 applies to anti-malware capabilities. Where removable media is permitted in the CDE, automatic scanning on connection is enforced by endpoint protection software. Device-control software complements this by restricting which devices can connect, reducing the attack surface that scanning must cover.
- Audit logs
Connection events, access approvals, and violations are logged with sufficient detail to support forensic review.
NIS2 removable-storage security requirements
How NIS2 applies to removable media
The NIS2 Directive establishes minimum cybersecurity risk-management obligations for essential and important entities operating in the EU. Article 21 requires covered entities to implement security measures proportionate to their risk, including access-control policies, asset management, and incident-prevention measures. Removable-media governance falls within these obligations where it is material to the organization's risk posture.
NIS2 versus Implementing Regulation 2024/2690
Commission Implementing Regulation (EU) 2024/2690 introduces more specific requirements for a defined subset of entities — including DNS providers, TLD registries, cloud services, data centers, content delivery networks, managed service providers, and certain digital service providers. For these entities, Section 12.3 of the implementing regulation specifies explicit removable-media obligations:
- Establish a removable-media policy governing use across the organization
- Technically prohibit removable-media connections unless an organizational reason exists
- Disable automatic execution of content from removable media
- Scan removable media for malicious code before use
- Protect portable storage devices during transit and storage
- Apply cryptographic protection where appropriate to the sensitivity of the data
These requirements apply only to entities within the scope of the implementing regulation, not to every NIS2-covered entity. Organizations should determine their applicable obligations before selecting controls.
Device-control measures that support NIS2
- Authorization and access control
Removable-media use is restricted to authorized users and devices. Unapproved connections are blocked and logged.
- Technical prohibition of unauthorized connections
Device-control software enforces the implementing regulation's requirement to prohibit connections unless an organizational reason exists, providing the technical layer behind the policy obligation.
- Autorun/autoplay disabling
Disabling automatic execution of removable-media content reduces the malware-introduction risk that the implementing regulation addresses. This can be enforced through endpoint configuration management alongside device-control policies.
- Malware scanning
The scanning requirement in 2024/2690 is an anti-malware capability. Device-control restrictions reduce the set of devices that require scanning by limiting which media can connect at all.
- Logging
Connection and file-transfer activity is logged with retention aligned to incident-response and reporting obligations.
How device control supports DORA compliance
DORA ICT risk-management expectations
The Digital Operational Resilience Act (DORA) applies to EU financial entities — including banks, insurers, investment firms, and payment service providers. Critical ICT third-party providers are subject to a separate EU oversight framework under DORA; their obligations differ from those of the financial entities they serve and should be assessed independently.
DORA requires covered financial entities to implement comprehensive ICT risk-management frameworks covering asset identification, risk assessment, protection measures, detection, response, and recovery. Removable-media governance is not explicitly named as a discrete requirement in DORA's primary text, but DORA's ICT risk-management obligations encompass the protection of ICT assets against unauthorized access, use, and disclosure — which includes peripheral and removable-media attack vectors where they are material to the entity's ICT risk profile.
Applying risk-based peripheral access controls
Financial entities implementing DORA's ICT risk-management framework should assess whether uncontrolled peripheral and removable-media access represents a material risk to their ICT systems. Where it does, proportionate access controls are appropriate. Device-control measures support DORA's protection objectives as a risk-based implementation, not as a direct mandate:
- Restricting ICT asset access to authorized users and approved devices
- Generating activity records that support incident detection and investigation
- Enforcing policies that limit the scope of potential data incidents
- Enabling documented exception management with audit trails
Evidence financial entities should retain
- Written removable-media policies reviewed at appropriate intervals
- Device-control configuration records showing approved and blocked device classes
- Access approval records for permitted removable media
- Connection and activity logs for the relevant retention period
- Exception records including justification, approver, scope, and expiration
- Evidence of periodic policy review and configuration testing
Australian ISM removable-media controls
Authorization and registration requirements
The Australian Government Information Security Manual (ISM) includes controls governing removable-media use across government systems. The ISM is updated regularly; all claims in this section should be verified against current control identifiers in the version published by the Australian Cyber Security Centre before publication or implementation.
The ISM addresses authorization of removable-media devices for use with specific systems, registration of devices with the organization, and assignment to an identifiable owner. Unregistered or unauthorized media should not be connected to in-scope systems.
Media classification, handling, and sanitization
The ISM requires that removable media be classified and handled in accordance with the information it carries. Sanitization requirements specify that media must be sanitized using approved methods before reuse on systems of lower classification or before disposal.
Device-control measures that support ISM implementation
- Hardware allowlisting
Only registered and authorized devices are permitted to connect to in-scope systems. Allowlists enforce this at the driver level.
- Device records
A register of approved removable media supports the ISM's ownership and registration expectations.
- Serial-number controls
Device-control software can enforce allowlists based on hardware-level identifiers, preventing connection of unregistered media.
- Activity logging
Connection and file-transfer activity supports security incident investigation and policy review.
Explicit device-control mandates vs. risk-based requirements
Organizations interpreting framework requirements should distinguish between three types of obligations:
| Requirement type | Meaning | Typical response |
|---|---|---|
| Explicit | The framework directly states a media-control obligation | Implement and document the stated control |
| Risk-based | The organization determines controls based on assessed risk | Block, restrict, or monitor devices according to risk |
| Supporting | A technical control helps satisfy a broader requirement | Document how the control supports the compliance objective |
Several factors determine which controls apply:
- Applicability and scoping
Framework obligations apply to specific entities, data types, and environments. Scoping analysis must precede control selection.
- Risk assessments
Risk-based frameworks require documented risk assessments to justify control choices. A control selected without a supporting risk assessment is difficult to defend to an auditor.
- Compensating controls
Where a prescribed control cannot be implemented, frameworks typically allow alternatives that achieve an equivalent objective. These must be documented and approved.
- Data classification
The sensitivity of data handled determines which controls are proportionate.
- Business exceptions
Legitimate operational requirements may make certain restrictions impractical in specific contexts. Exceptions should be formally requested, reviewed, approved, time-limited, and documented.
Technical device controls used for compliance
The table below maps core device-control capabilities to the risk they address, relevant frameworks, and the evidence they generate. Encryption and malware scanning are complementary controls implemented through separate security tools; they appear where they interact with device-control policy.
| Technical control | Risk addressed | Framework relevance | Evidence generated |
|---|---|---|---|
| Block unauthorized device classes | Unrestricted access enabling exfiltration and malware introduction | NIST, ISO 27001, PCI DSS, NIS2, DORA, ISM | Blocked-connection logs with device class, user, endpoint, timestamp |
| Allow approved devices by VID, PID, or serial number | Use of unidentifiable or unregistered media | NIST (identifiable owner), ISM (serial-number registration), ISO 27001 (accountability) | Allowlist configuration, approved-device register, connection logs |
| Enforce read-only access | Data exfiltration via write to removable media | ISO 27001, PCI DSS, NIS2, DORA | Read-only policy configuration, file-activity logs |
| Restrict file types and transfer sizes | Targeted exfiltration; introduction of executable malware | NIS2, DORA, PCI DSS | File-transfer logs, blocked-transfer records |
| Coordinate with removable-media encryption tools | Data exposure from lost or improperly disposed media | ISO 27001, NIST, PCI DSS, ISM | Encryption policy records, compliance reports |
| Grant temporary, time-bound access | Uncontrolled exception management | NIST, ISO 27001, PCI DSS, DORA | Request and approval records, access-grant and expiration timestamps |
| Record device connections and file activity | Inability to detect violations, investigate incidents, or demonstrate enforcement | NIST, PCI DSS, NIS2, DORA, ISM, ISO 27001 | Connection logs, file-transfer logs, violation logs, exportable reports |
| Alert administrators to policy violations | Delayed detection of active violations | NIS2, DORA, NIST, ISO 27001 | Alert logs, incident records, response documentation |
| Scan removable media for malware (anti-malware tool) | Malware introduction via removable media | PCI DSS Req. 5.3.3, NIS2 Reg. 2024/2690, ISM | Scan records, detection events (requires endpoint protection software) |
How to prove device-control compliance to auditors
A written policy is necessary but not sufficient. Auditors expect evidence of continuous enforcement across the assessment period. The following table covers core control objectives and the evidence that supports them.
Device-control audit evidence checklist
| Control objective | Evidence to retain |
|---|---|
| Unauthorized devices are blocked | Device-control policy and blocked-connection logs |
| Approved devices are identifiable | Serial number, assigned owner, and approval records |
| Access is appropriately restricted | Read/write permission configurations |
| Exceptions are controlled | Request, approval, justification, scope, and expiration |
| Device activity is monitored | Connection, file-transfer, and violation logs |
| Permitted data is protected | Encryption policy records and compliance reports |
| Policies remain effective | Review records, configuration changes, and periodic reports |
The gap between "we have a policy" and "we can demonstrate the policy was enforced throughout the period" is a common source of audit findings. Device-control software that generates continuous, exportable logs addresses this gap directly.
Log retention periods should align with the applicable framework's requirements, contractual obligations, and organizational incident response needs. PCI DSS specifically requires audit log retention for at least 12 months, with the most recent three months immediately available. Other frameworks set their own retention expectations; organizations should apply the requirement relevant to each applicable standard rather than assuming a single period covers all obligations.
Device-control compliance checklist
- Identify all removable-media and peripheral device types used across your environment.
- Define which users and endpoints require removable-media access, and document the business justification.
- Block unauthorized device classes by default on all in-scope endpoints.
- Allow approved devices using unique hardware identifiers (VID, PID, or serial number).
- Apply read-only access where write access is unnecessary.
- Coordinate with removable-media encryption tools where sensitive data requires protection in transit.
- Establish a documented exception workflow with formal request, approval, scope, and expiration.
- Automatically expire temporary permissions without requiring manual revocation.
- Record device connections and file transfers with sufficient detail for audit and investigation.
- Alert administrators to violations in real time or near-real time.
- Review approved-device inventories at defined intervals and after personnel changes.
- Retain audit evidence according to applicable framework requirements and organizational retention policies.
- Test device-control policies across both remote and on-premises endpoints to confirm consistent enforcement.
How Device Control Plus supports compliance
Device Control Plus provides centralized control over peripheral and removable-media access across organizational endpoints, enabling IT and security teams to define, enforce, and document device policies at the organizational, group, or endpoint level.
- Centralized peripheral access policies
Policies are defined once and applied consistently across managed endpoints, including remote devices, reducing configuration drift and unmanaged exceptions.
- Device-class and device-level restrictions
Administrators can block entire device classes or restrict access to specific approved devices, applying the appropriate level of granularity for the endpoint's risk profile.
- VID, PID, and serial-number controls
Allowlists based on hardware-level identifiers ensure only registered, approved devices can connect. This directly addresses the NIST requirement to prohibit use of media without an identifiable owner and supports ISM serial-number registration expectations.
- Read-only access enforcement
Read-only policies can be applied at the user, group, or endpoint level, limiting exfiltration risk while preserving workflows that depend on receiving data from external media.
- Temporary access management
Controlled, time-bound access grants are documented automatically, with expiration enforced without manual follow-up, supporting exception governance requirements across frameworks.
- File-transfer monitoring
File-level activity on connected removable media is recorded, including file name, type, direction, user, and endpoint, providing the continuous enforcement evidence auditors expect.
- Device activity reports
Exportable reports provide audit-ready summaries of device connections, policy violations, approved-device activity, and exception history across the assessment period.
- Policy-violation visibility
Administrators are alerted to unauthorized connection attempts and blocked transfers, supporting the detection and response capabilities expected under NIS2 and DORA.
For encryption of data on permitted media and malware scanning of removable media, Device Control Plus works alongside dedicated encryption and endpoint protection tools. Effective removable-media compliance programs typically combine controls from multiple product categories.
